Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
26832
Total
1978
Critical
8053
High
8297
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-50223 | HIGH | 8.8 | Improper Control of Generation of Code ('Code Injection') vulnerability in Apache OFBiz allows a low-privileged authenticated user with Content/DataResource editing privileges to perform template injection … | Jun 10, 2026 |
| CVE-2026-49219 | MEDIUM | 5.5 | ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-48 and 7.1.2-24, an incorrect parsing of the filename … | Jun 10, 2026 |
| CVE-2026-49218 | HIGH | 7.5 | ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-48 and 7.1.2-24, a missing check in the DCM … | Jun 10, 2026 |
| CVE-2026-48994 | MEDIUM | 5.9 | ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-48 and 7.1.2-24, a missing check of a return … | Jun 10, 2026 |
| CVE-2026-48734 | MEDIUM | 5.5 | ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-49 and 7.1.2-24, a crafted MVG file could result … | Jun 10, 2026 |
| CVE-2026-48733 | MEDIUM | 4.7 | ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-49 and 7.1.2-24, an infinite loop in the subimage-search … | Jun 10, 2026 |
| CVE-2026-48724 | MEDIUM | 5.5 | ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to version 7.1.2-24, when using an image with mask the Floyd-Steinberg … | Jun 10, 2026 |
| CVE-2026-47734 | MEDIUM | 5.7 | Dulwich is a pure-Python implementation of the Git file formats and protocols. Starting in version 0.1.0 and prior to version 1.2.5, a client with push … | Jun 10, 2026 |
| CVE-2026-47712 | LOW | 3.3 | Dulwich is a pure-Python implementation of the Git file formats and protocols. Starting in version 0.24.0 and prior to version 1.2.5, dulwich.porcelain.format_patch(outdir=...) derives each patch … | Jun 10, 2026 |
| CVE-2026-47342 | UNKNOWN | — | A privilege escalation vulnerability in Apache OFBiz allows a low-privileged authenticated user to obtain higher privileges This issue affects Apache OFBiz: before 24.09.07. Users are … | Jun 10, 2026 |
| CVE-2026-47213 | MEDIUM | 6.5 | Boxlite is a sandbox service that allows users to create lightweight virtual machines (Boxes) and launch OCI containers within them to run untrusted code. In … | Jun 10, 2026 |
| CVE-2026-47166 | MEDIUM | 5.7 | ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-48 and 7.1.2-23, an attacker who can connect to … | Jun 10, 2026 |
| CVE-2026-47165 | MEDIUM | 4.1 | ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-48 and 7.1.2-23, the distributed pixel cache was originally … | Jun 10, 2026 |
| CVE-2026-46703 | CRITICAL | 9.6 | Boxlite is a sandbox service that allows users to create lightweight virtual machines (Boxes) and launch OCI containers within them to run untrusted code. Prior … | Jun 10, 2026 |
| CVE-2026-46695 | CRITICAL | 10.0 | Boxlite is a sandbox service that allows users to create lightweight virtual machines (Boxes) and launch OCI containers within them to run untrusted code. Prior … | Jun 10, 2026 |
| CVE-2026-46693 | MEDIUM | 4.1 | ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-48 and 7.1.2-23, an attacker who can connect to … | Jun 10, 2026 |
| CVE-2026-46692 | MEDIUM | 4.1 | ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-48 and 7.1.2-23, an attacker who can connect to … | Jun 10, 2026 |
| CVE-2026-46645 | MEDIUM | 4.3 | SQLAdmin is a flexible Admin interface for SQLAlchemy models. Prior to version 0.25.1, the ajax_lookup endpoint in application.py bypasses the is_accessible() access control check that … | Jun 10, 2026 |
| CVE-2026-46559 | MEDIUM | 4.0 | ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-48 and 7.1.2-23, an incorrect check in the JP2 … | Jun 10, 2026 |
| CVE-2026-46557 | MEDIUM | 6.2 | ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to version 7.1.2-23, due to a missing depth check a stack … | Jun 10, 2026 |
| CVE-2026-46521 | MEDIUM | 5.5 | ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-48 and 7.1.2-23, when using LZMA compression in the … | Jun 10, 2026 |
| CVE-2026-44693 | HIGH | 8.8 | Pi-hole FTL is the core engine of the Pi-hole network-level advertisement and tracker blocker. Prior to version 6.6.1, Pi-hole FTL contains a race condition vulnerability … | Jun 10, 2026 |
| CVE-2026-42568 | MEDIUM | 4.3 | Yamcs is a mission control framework. Prior to versions 5.13.0 and 5.12.7, an LDAP injection vulnerability exists in `org.yamcs.security.LdapAuthModule` when constructing search filters. The username … | Jun 10, 2026 |
| CVE-2026-42563 | UNKNOWN | — | Dulwich is a pure-Python implementation of the Git file formats and protocols. Starting in version 0.24.0 and prior to version 1.2.5, Dulwich's `ProcessMergeDriver` substitutes the … | Jun 10, 2026 |
| CVE-2026-42558 | HIGH | 7.6 | Xibo is an open source digital signage platform with a web content management system and Windows display player software. Prior to 4.4.2, a vulnerability chain … | Jun 10, 2026 |